CVE-2020-7051

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/02/2020
Last modified:
28/06/2022

Description

Codologic Codoforum through 4.8.4 allows stored XSS in the login area. This is relevant in conjunction with CVE-2020-5842 because session cookies lack the HttpOnly flag. The impact is account takeover.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:codologic:codoforum:*:*:*:*:*:*:*:* 4.8.4 (including)